Skip to content
CAI
Software that uses CAICheck a score

rubygems/rubygems.org

49.0

Weak · 19 September 2026

25.3k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the RubyGems.org application, a platform for hosting and distributing Ruby software packages. It provides core functionality for users to manage gem versions, handle ownership and organizational structures, and interact with a comprehensive REST API for programmatic access. The system also features a secure, GitHub-authenticated admin dashboard for monitoring metrics, auditing changes, and performing maintenance tasks on the gem ecosystem.

How it got here

2009–2014 — Platform modernization and security hardening

45 changes.

This period focused on a comprehensive modernization of the RubyGems.org platform, upgrading the core stack to Rails 8.1 and Ruby 3.4 while implementing a new Docker-based development environment. Significant effort was dedicated to security hardening through the introduction of API key management, OIDC integration, HIBP password checks, and Sigstore attestation support. The work also encompassed a complete UI redesign with Tailwind CSS, a migration to Playwright for testing, and the restructuring of the API and background job infrastructure.

2015–2023 — OIDC integration and admin overhaul

85 changes.

This period focused on implementing OpenID Connect support for trusted publishers and API key roles, alongside a comprehensive redesign of the admin dashboard using Avo and GitHub OAuth. The work also included migrating the view layer to Phlex, standardizing styling with Tailwind CSS, and significantly expanding test coverage across API, model, and administrative features.

2024–2026 — Organizations and security infrastructure

43 changes.

This period focused on introducing multi-tenant organization management, including onboarding flows, membership controls, and gem transfer workflows. It also established a robust security foundation through structured event logging, RSTUF artifact integration, and comprehensive API authorization policies. The frontend was modernized by migrating to vanilla JavaScript and Stimulus, while the admin panel was upgraded to Avo 3.

Features

Add Rails 4-style binstubs and development tooling scripts

The bin directory now includes standard Rails binstubs (rails, rake, bundle) alongside new scripts for development and testing: bin/ci for local continuous integration, bin/dev for running the Rails server, bin/herb for HTML parsing, bin/importmap for asset management, bin/playwright and bin/prettier for system testing and JavaScript linting, bin/brakeman and bin/rubocop for security and code quality checks, and bin/setup/bin/update for environment provisioning and database migrations.

bin · high confidence

Add WebAuthn credential management UI

Users can now register and manage WebAuthn security devices directly from the profile view. The new interface includes a form to add a new device with a nickname and a list view to display existing credentials, each with a delete button that prompts for confirmation before removal.

_app/views/webauthn\credentials · high confidence

Add internal ping and revision endpoints

The application now exposes two new internal API endpoints for health monitoring and version tracking. The /ping endpoint returns a simple "PONG" response to verify service availability, while the /revision endpoint returns the current application version string via AppRevision.version, allowing operators to confirm which code version is currently deployed.

app/controllers/internal · high confidence

Add organization invitation email templates

Added HTML and text email templates for the organization invitation flow, allowing users to receive notifications when invited to join an organization. The HTML template includes a styled 'ACCEPT INVITATION' button, while the text template provides a plain-text version with the acceptance URL.

_app/views/organization\mailer · high confidence

Admin audit trail now shows detailed field-level diffs

Administrators can now view a structured, field-by-field comparison of record changes within the Avo admin interface. This new \AuditedChangesRecordDiff::ShowComponent\ renders a visual diff that highlights added, modified, and removed fields using distinct color coding (green for new, orange for changed, red for old), allowing admins to quickly understand exactly what data was altered in an audit entry.

_app/components/avo/audited\_changes\_record\diff · high confidence

Admin dashboard now displays a personalized welcome card

The admin dashboard now includes a new welcome card component that displays a message identifying the currently logged-in administrator. This card provides a direct link to the admin user's profile page, allowing for quick navigation to account details upon logging into the Avo admin interface.

app/views/avo/cards · high confidence

Custom Avo field implementations for arrays, nested records, and JSON viewing

The admin interface now includes several new custom Avo field types to improve data handling and display. The ArrayOfField and NestedField allow for the editing and display of complex, nested data structures within resources. A new JsonViewerField provides a formatted, syntax-highlighted view for JSON content. Additionally, the GlobalIdField and SelectRecordField offer specialized handling for GlobalID references and record selection, while the EventAdditionalField dynamically renders event-specific attributes based on their type.

app/avo/fields · high confidence

Expanded admin dashboard resource coverage

The admin dashboard now includes dedicated resource controllers for a broader set of data models, enabling administrators to view and manage additional entities directly. New controllers have been added for GitHub users, API keys and their scopes, attestations, audit logs, blocked email domains, deletions, dependencies, email allowlists, event associations, gem downloads, gem name reservations, gem typo exceptions, GeoIP info, IP addresses, link verifications, link sets, log tickets, maintenance task runs, memberships, OIDC providers and roles, pending trusted publishers, organization invites and onboarding, organizations, ownerships, RubyGems, SendGrid events, subscriptions, users, versions, webhooks, and WebAuthn credentials. This expands the administrative interface's visibility into system state and operational records.

app/controllers/avo · high confidence

Initial RSTUF API client implementation

Added a new RSTUF API client (\lib/rstuf/client.rb\) that enables interaction with the RSTUF service. This client provides methods to post and delete artifacts, as well as check the state of tasks, using Faraday for HTTP communication and JSON serialization. It includes error handling for API failures and logging capabilities.

lib/rstuf · high confidence

Initial database schema and ownership model

The database is initialized with core tables for users, rubygems, versions, and dependencies, establishing the foundational data structure. A dedicated ownership model is introduced via the \ownerships\ table to manage gem permissions, replacing the previous single-owner design where \user\_id\ was stored directly on the \rubygems\ table. This change also includes the creation of supporting tables for linksets, subscriptions, web hooks, and delayed jobs, along with the initial indexing strategy to support query performance.

db/migrate · high confidence

Initial implementation of RSTUF artifact management jobs

Added a new set of background jobs (\Rstuf::AddJob\, \Rstuf::RemoveJob\, \Rstuf::CheckJob\) to handle uploading and deleting gem artifacts via the RSTUF service. \AddJob\ and \RemoveJob\ submit tasks to the RSTUF client and trigger a subsequent check, while \CheckJob\ monitors task status, supporting a new \PRE\_RUN\ state and implementing retry logic for transient states like \PENDING\ or \RUNNING\. The jobs are gated by \Rstuf.enabled?\ to ensure they only run when the feature is active.

app/jobs/rstuf · high confidence

Introduce OIDC-based trusted publisher and API key role models

This change adds the foundational data models for OIDC integration, enabling users to configure trusted publishers (currently GitHub Actions) and manage API key roles. The new \OIDC::Provider\ model stores OIDC provider configurations and JWKS, while \OIDC::ApiKeyRole\ links a user to a provider and defines permissions via \OIDC::ApiKeyPermissions\ (scopes and gem ownership). \OIDC::AccessPolicy\ allows fine-grained JWT validation using conditions like \string\_equals\ or \string\_matches\. \OIDC::IdToken\ records issued tokens, and \OIDC::PendingTrustedPublisher\ / \OIDC::RubygemTrustedPublisher\ handle the association of trusted publishers with specific gems, including validation for reserved names and availability.

app/models/oidc · high confidence

Introduce new model classes for API keys, attestations, and admin auditing

This change adds several new model classes to the application: \ApiKey\ (with polymorphic ownership, scopes, and MFA checks), \ApiKeyRubygemScope\ (linking API keys to specific gems), \Attestation\ (storing and validating Sigstore bundles), \Audit\ (tracking admin actions), \BlockedEmailDomain\ (managing email domain restrictions), \Admin::GitHubUser\ (storing admin GitHub users), \ApplicationModel\ (base for non-AR models), and \ApplicationRecord\ (base for AR models). These models support new features like API key management, gem attestation verification, admin auditing, and email domain blocking.

app/models · high confidence

Introduce organization management capabilities

This change introduces the backend controllers for the new Organizations feature, enabling users to create and manage organizational structures. Key capabilities include inviting and managing members (with support for resending invitations), reserving gem names, and viewing organization-owned gems. The implementation includes a base controller that enforces sign-in and MFA requirements, and specific controllers for handling membership invitations, member lists, gem name reservations, and onboarding completion.

app/controllers/organizations · high confidence

Introduce organization onboarding flow

Adds a new multi-step onboarding process for creating organizations, implemented via a dedicated controller namespace under app/controllers/organizations/onboarding. The flow guides users through setting the organization name and handle, selecting RubyGems to include, inviting team members (with the creator automatically assigned as owner), and confirming the setup. The controllers enforce authentication, MFA requirements, and feature flags, and use a shared layout and breadcrumbs for consistent navigation.

app/controllers/organizations/onboarding · high confidence

Introduce structured security and activity event logging

The application now records detailed, structured events for key user and system actions, including user account creation, login success, email changes, API key management, and RubyGem version pushes, yanks, and owner changes. This new event system captures contextual metadata such as IP address, geolocation, and parsed user-agent information (browser, OS, installer) to provide a comprehensive audit trail for security monitoring and administrative oversight.

app/models/events · high confidence

Introduces custom ActiveModel types for arrays, durations, GlobalIDs, and JSON

The application now includes four new custom type definitions in lib/types to handle specific data casting and serialization needs. The new Types::ArrayOf allows for generic array validation with member casting, while Types::Duration provides robust parsing and serialization of time intervals from strings, integers, or existing duration objects. Types::GlobalId simplifies the handling of GlobalID objects by automatically parsing string representations, and Types::JsonDeserializable ensures safe JSON serialization by normalizing nested structures to prevent unexpected output from Rails 8.1's JSON encoder.

lib/types · high confidence

New Admin GitHub User model for storing and validating admin accounts

A new \Admin::GitHubUser\ model has been added to persist GitHub user data for administrators. This model validates that admin users have the necessary OAuth tokens and info data, ensures they are members of the RubyGems organization, and provides methods to check team membership. It also sets up associations for auditing admin actions.

app/models/admin · high confidence

New Kubernetes deployment manifests for web, background jobs, and infrastructure

This change introduces a comprehensive set of Kubernetes configuration files for the application's deployment. The web service is now deployed as a Puma-based application with Datadog AppSec enabled, health probes, and resource limits. Background processing is handled by dedicated Good Job deployments for default, maintenance, and 'within 24 hours' queues, as well as a Shoryuken deployment for SQS-based tasks. Infrastructure includes a new Ingress resource using the networking.k8s.io/v1 API, an Nginx sidecar configuration for rate limiting and proxying, a CronJob for monthly version list updates, and a dedicated Pod for database migrations.

config/deploy · high confidence

New OIDC API endpoints for role assumption, trusted publishers, and token exchange

This change introduces a new set of API controllers under the OIDC namespace, enabling programmatic interaction with OpenID Connect features. The \ApiKeyRolesController\ allows users to list and assume OIDC API key roles, generating temporary API keys based on validated JWTs. The \TrustedPublisherController\ provides an endpoint to exchange OIDC tokens for RubyGems API keys, facilitating trusted publishing workflows. Additionally, the \RubygemTrustedPublishersController\ exposes CRUD operations for managing trusted publisher configurations on specific gems, while \ProvidersController\ and \IdTokensController\ provide read access to OIDC provider metadata and issued ID tokens respectively.

app/controllers/api/v1/oidc · high confidence

New OIDC API key roles and trusted publisher management interfaces

The application now provides dedicated controllers and views for managing OIDC (OpenID Connect) integration features. Users can create and manage API key roles with specific scopes and access policies via the new \OIDC::ApiKeyRolesController\. Additionally, new controllers handle the lifecycle of trusted publishers: \OIDC::PendingTrustedPublishersController\ allows users to create and manage pending publisher requests, while \OIDC::RubygemTrustedPublishersController\ enables gem maintainers to configure trusted publishers directly on their gem pages. Supporting controllers for OIDC providers (\OIDC::ProvidersController\) and ID tokens (\OIDC::IdTokensController\) are also introduced to allow users to view provider details and token history. These changes introduce stricter parameter validation using \params.expect\ and integrate session verification for security.

app/controllers/oidc · high confidence

New RubyGems transfer workflow for organizations

Users can now transfer ownership of RubyGems to an organization through a new multi-step onboarding flow. This change introduces a dedicated controller hierarchy (base, organizations, rubygems, users, confirmations, and transfers) that guides users through selecting a target organization, choosing which gems to transfer, assigning member roles, and confirming the action. The system supports bulk transfers in a single transaction and allows users to cancel pending or failed transfers.

app/controllers/rubygems · high confidence

New administrative rake tasks for data integrity, security, and maintenance

This change introduces a suite of new Rake tasks in lib/tasks to support various administrative and maintenance operations. Key additions include api\_keys:migrate to migrate legacy user API keys to the new ApiKey model, multifactor\_auth:migrate\_ui\_only to update user MFA levels, and audit\_attestation\_subject\_digest to verify attestation integrity against version SHA256 hashes. Data integrity is improved with tasks like compact\_index:correct\_info\_checksum, compact\_index:backfill\_yanked\_at, dependency:dangling\_rubygem\_id\_purge, and linkset:clean to fix checksums, backfill missing fields, and remove invalid URLs. Operational tasks include gemcutter:import:process for bulk gem imports, gemcutter:gem\_downloads:add\_rubygems\_record for download tracking, users:verify to block users with expired email domains, and memcached:flush for cache management. Developer tooling is also enhanced with format:ruby and format:js for code formatting, importmap:verify and importmap:pristine for JavaScript package management, and gen\_erd for generating entity-relationship diagrams.

lib/tasks · high confidence

New administrative scripts for user and gem management

A suite of new command-line scripts has been added to the \script/\ directory to streamline administrative tasks. These include \add\_owner\ to grant gem ownership, \block\_user\ to disable user accounts, \change\_email\ to update user email addresses, and \merge\_users\ to consolidate duplicate accounts. Security and maintenance capabilities are expanded with \disable\_mfa\ to reset two-factor authentication, \permadelete\ to permanently remove gems, \restore\_version\ to recover yanked gems, \reset\_api\_key\ to regenerate API keys, and \yank\_gem\ or \yank\_user\ to yank specific gems or all gems associated with a user. Additional utility scripts include \load-pg-dump\ for restoring database dumps, \release\_reserved\_namespace\ for freeing gem names, \update-rubygems\ for updating Ruby and RubyGems versions in the project configuration, \build\_docker.sh\ for building and testing Docker images, \dev\ for loading development secrets, and \s3\_utils.rb\ for S3 object management.

script · high confidence

New auditing capability for Avo resources

Added the \Auditable\ concern to Avo resources, enabling automatic tracking of database changes. This concern wraps create, update, and destroy actions in transactions, capturing before-and-after attribute states for all affected records and storing them in a new \Audit\ model. It also includes logic to normalize complex data structures for JSON serialization to ensure compatibility with Rails 8.1's JSON encoder.

app/avo/concerns · high confidence

New dedicated page for managing notification preferences

Users can now configure push and owner notification settings for their individual gems and organization memberships on a dedicated Notifiers page. The new interface allows users to toggle push notifications and owner notifications on or off for each gem they own and each organization they belong to, with recommended defaults indicated.

app/views/notifiers · high confidence

New email and scope boolean filters for admin dashboard

The admin dashboard now includes two new filter components: an Email filter that allows searching by email address using regular expressions, and a ScopeBoolean filter that enables filtering by multiple boolean scopes with default values. These additions enhance the admin interface's data filtering capabilities.

app/avo/filters · high confidence

New email notification for policy updates

Users will now receive an email announcement informing them that RubyGems.org is adopting new Terms of Service, Privacy Notice, Acceptable Use Policy, and Copyright Policy. The message details the review period concluding on June 4th and explains that a banner will appear on the site afterward prompting users to review and accept the new policies.

_app/views/policies\mailer · high confidence

New helper modules for API keys, OIDC, and ownership management

This change introduces a suite of new view helper modules to support recent feature additions in the application. The new \ApiKeysHelper\ provides logic for displaying API key scopes, including tooltips for soft-deleted gems, and manages the parameter processing for API key creation and updates. \OwnersHelper\ adds policy-based checks for adding, modifying, and removing gem owners, as well as displaying MFA and confirmation status. \OIDC::ApiKeyRolesHelper\ and \OIDC::ProvidersHelper\ are added to support the new OIDC integration for API keys. Additionally, \ApplicationHelper\ is updated with new methods for page titles, avatar rendering, and search fields, while \RubygemsHelper\ gains methods for subscription links, license display, and various sidebar links. Other new helpers include \AttestationsHelper\, \DurationHelper\, \DynamicErrorsHelper\, \IconHelper\, \ProseHelper\, \SearchesHelper\, \UsersHelper\, and \VersionsHelper\, each providing specific UI logic for their respective domains.

app/helpers · high confidence

New helper modules for compact index checksums and importmap verification

Added two new helper modules in lib/tasks/helpers: CompactIndexTasksHelper, which updates info checksums for gem versions (handling both indexed and yanked states), and ImportmapHelper, which provides a custom packager to verify and manage vendored JavaScript packages via jspm.io, including diff generation for verification failures.

lib/tasks/helpers · high confidence

New library modules for security, validation, and infrastructure

This change introduces a suite of new library components to enhance security, validation, and infrastructure management. Security is strengthened with \PasswordBreachChecker\ to validate passwords against the HIBP database, \GitHubSecretScanning\ for verifying secret scanning signatures, and \SearchQuerySanitizer\ to protect the search engine from DoS attacks by sanitizing user queries. Validation is improved with \GemValidator\ (including schema and package validation), \GemRequirementsValidator\, and \NameFormatValidator\ to enforce stricter gem metadata rules. Infrastructure and operational capabilities are added via \RubygemFs\ for S3/local storage abstraction, \Fastly\ for cache purging, \GemCachePurger\ for cache invalidation, \ElasticSearcher\ for search operations, and \Access\ for role-based permissions. Additional utilities include \AppRevision\ for version tracking, \CertificateChainSerializer\ for certificate handling, \ClearanceBackdoor\ for development login, \CompactIndex\ for vendored index logic, \ConfirmedUserGuard\ for email confirmation enforcement, \GemPackageEnumerator\ for efficient gem reading, \GitHubOAuthable\ for admin authentication, \JobTags\ for job tracking, \NestedValidator\ for complex validation, \Patterns\ for shared regex definitions, \RackAttackReset\ for rate-limit management, \RailsDevelopmentLogFormatter\ for logging, \Rstuf\ for feature toggling, \ShasumFormat\ for checksum handling, and \TraceTagger\ for Datadog integration.

lib · high confidence

New maintenance tasks for data integrity, security, and infrastructure

This update introduces a suite of new maintenance tasks to the application. For security and user management, it adds tasks to revoke cache-exposed API keys, notify affected users (including staggered notifications for inactive users), discard spam accounts, and yank/block users associated with specific API keys. For data integrity and backfilling, new tasks repair broken attestations, backfill gem platform information, populate spec SHA-256 checksums, link set links to version metadata, and backfill user WebAuthn IDs. Additionally, infrastructure tasks are added to verify gem contents in storage, upload info files to S3, and backfill compact index v2 information.

app/tasks · high confidence

New model concerns for MFA, search, and data integrity

This change introduces several new concerns in app/models/concerns. UserMultifactorMethods, UserTotpMethods, and UserWebauthnMethods consolidate and refactor multi-factor authentication logic, including TOTP and WebAuthn verification, MFA level management, and recovery code handling. RubygemSearchable integrates Searchkick for gem search, defining mappings and search data structures. CompactIndexVersions provides methods for generating compact index data. EmailDomainNormalization adds validation for email domains. PasswordResettable implements secure password reset token handling. AttestationBundleRepair adds logic to fix issues in Sigstore attestation bundles.

app/models/concerns · high confidence

New news page with tabbed navigation and pagination

A new view for the news section has been added, featuring a tabbed interface that allows users to toggle between 'All Gems' and 'Popular Gems'. The page displays a list of Ruby gems using a dedicated component and includes pagination controls to navigate through entries, with an info header indicating the current page range.

app/views/news · high confidence

New organization management interface with membership, gem, and reservation views

Users can now manage organizations through a dedicated set of views. The main dashboard lists all organizations the user belongs to and allows creating new ones. Inside an organization, users can view a history of gem activity, manage the list of gems owned by the organization, and view/edit member lists with invite capabilities. Additionally, organization owners can reserve gem names and edit organization settings like the display name.

app/views/organizations · high confidence

New owner notification and confirmation email templates

The owners mailer now uses new HTML and text email templates for notifying users when they are added to, removed from, or have their ownership role updated on a gem. These notifications include security guidance for unexpected changes and links to manage email preferences. Additionally, a new ownership confirmation flow has been introduced, requiring users to verify their ownership via a secure link with an expiration time.

_app/views/owners\mailer · high confidence

New password change and compromised password reset email templates

Users will now receive newly designed HTML and plain-text emails for password changes and compromised account notifications. The 'change password' email provides a direct link to reset the password, while the 'compromised password reset' email includes additional reassurance text and a link that specifies the reason for the reset, along with support contact information.

_app/views/password\mailer · high confidence

New v2 API endpoints for gem contents checksums and version details with Ruby ABI support

This change introduces two new controllers in the v2 API: \Api::V2::ContentsController\ and \Api::V2::VersionsController\. The contents controller exposes a new endpoint to retrieve content-addressable checksums (SHA256) for specific gem versions, supporting JSON, YAML, and plain text responses, while also validating that the requested version has associated checksums. The versions controller provides detailed payload information for a specific gem version, including platform and Ruby ABI variant resolution. Both endpoints now support filtering by \ruby\_abi\ (e.g., 3.2) alongside platform and version number, allowing users to target specific Ruby ABI variants when resolving and fetching version data. The implementation includes caching headers consistent with v1, strong parameter validation, and specific error handling for missing versions or unavailable content.

app/controllers/api/v2 · high confidence

Project initialization and development environment setup

This change establishes the foundational configuration for the RubyGems.org application, including a new Dockerfile for multi-stage builds, a docker-compose.yml for local services (PostgreSQL, Memcached, OpenSearch, Toxiproxy), and a .ruby-version file specifying Ruby 4.0.6. It introduces comprehensive linting and formatting rules via .rubocop.yml (targeting Ruby 4.0, using Prism parser) and .prettierignore, alongside a new .herb.yml for HTML validation. Documentation is updated with AGENTS.md for AI coding guidance, a new SECURITY.md, and a rewritten CONTRIBUTING.md detailing setup via Docker or DevContainers. The deployment tooling is updated to use Krane for Kubernetes, and the README is converted from Textile to Markdown.

(repo-wide) · high confidence

The site now includes dedicated, viewable pages for its core legal policies: Terms of Service, Privacy Notice, Acceptable Use Policy, and Copyright Policy. These pages are rendered from Markdown files and linked from a new policies index, providing users with clear, accessible information on account security, data handling (including the use of ClickHouse for log analysis), content ownership, and enforcement procedures.

app/views/policies · high confidence

Staging deployment configuration and secrets initialization

The staging environment is now configured with a complete set of Kubernetes deployment manifests (web, jobs, shoryuken, maintenance, db-migrate) and ingress rules, all linked via symlinks to shared templates. A new encrypted secrets file (secrets.ejson) has been added, provisioning essential credentials for the staging instance, including database access, AWS keys, Sendgrid email services, GitHub OAuth, Avo admin license, and basic authentication for the UI.

config/deploy/staging · high confidence

Support for GitHub Actions as an OIDC trusted publisher

Users can now configure GitHub Actions workflows as trusted publishers for their gems. This change introduces a new model that validates repository, workflow, and environment details, and enables the system to verify OIDC tokens issued by GitHub Actions. It also adds support for verifying sigstore attestations generated by these workflows, ensuring that only authorized CI/CD pipelines can publish packages.

_app/models/oidc/trusted\publisher · high confidence

Security

New security incident notifications and standardized email templates

Users will now receive specific security notices regarding a legacy API key exposure incident ([GHSA redacted]), with separate emails for accounts where keys were already inactive versus those where active keys were revoked and require re-authentication. The email system has also been updated with a new standardized layout, including a reusable button component, dedicated templates for API key creation and revocation, and improved instructions for compromised accounts.

app/views/mailer · high confidence

Behavioural changes

API authorization now enforced via Pundit policies

API endpoints for RubyGems, ownership, and webhooks now require explicit authorization checks using Pundit policies. Access is determined by a combination of API key scopes (such as push\_rubygem, add\_owner, or access\_webhooks) and user-level permissions, with Multi-Factor Authentication (MFA) requirements enforced for sensitive actions like creating gems or modifying ownership. This change ensures that API requests are validated against specific scope permissions and user roles before execution.

app/policies/api · high confidence

API controllers refactored into a centralized base controller with new compact index and deprecation endpoints

The API controller structure has been reorganized to improve security, maintainability, and performance. A new \Api::BaseController\ centralizes common logic, including API key authentication, MFA verification, Pundit authorization, and session skipping, while removing the need for individual controller boilerplate. A new \Api::CompactIndexController\ implements the v2 compact index protocol, supporting range requests, ETags, and SHA-256 digests for efficient gem metadata retrieval. Additionally, an \Api::DeprecatedController\ now returns a 403 Forbidden status for legacy plugin versions, guiding users to update. These changes streamline API access control and enhance response caching and integrity verification for gem consumers.

app/controllers/api · high confidence

Add Pundit policies for OIDC trusted publishers

New authorization policies have been introduced for managing OIDC trusted publishers, restricting access based on user ownership and organizational roles. The \PendingTrustedPublisherPolicy\ allows users to view, create, and delete pending publisher records only for records they own. The \RubygemTrustedPublisherPolicy\ restricts viewing, creating, and deleting trusted publisher records for a specific Ruby gem to users who are owners of that gem and hold at least the admin role within the associated organization.

app/policies/oidc · high confidence

Admin actions migrated to a unified, audited base class

The admin panel's Avo actions now inherit from a new \ApplicationAction\ base class that enforces a mandatory audit comment (minimum 10 characters) and wraps every operation in an audited transaction, ensuring all administrative changes are logged. This refactor also standardizes error handling by reporting exceptions via \Rails.error\ and keeps the UI modal open on failure, while preserving the specific capabilities of each action such as user deletion, API key management, and gem yanking.

app/avo/actions · high confidence

Admin authorization now uses a custom Pundit client to scope policies

The admin interface now uses a dedicated \Admin::AuthorizationClient\ to handle authorization checks. This change ensures that Pundit policies for admin resources are automatically scoped under the \:admin\ namespace, keeping them separate from global policies and allowing for more granular access control within the admin area.

lib/admin · high confidence

Admin dashboard now displays key metrics and push activity charts

The admin dashboard has been updated to include a new layout with specific metric cards and a chart. Users can now see the total number of users, as well as counts for RubyGems and versions pushed, with the latter two supporting time-range filters (7 days, 30 days, 60 days, 365 days, Today, Month to date, Quarter to date, Year to date, and All). Additionally, a line chart visualizes the number of pushes by day over the last 30 days. These components are arranged in a grid and are visible only to users with the 'rubygems-org' team membership.

app/avo/cards, app/avo/dashboards · high confidence

Admin namespace protected by GitHub OAuth

The new admin dashboard area is now secured by requiring GitHub OAuth authentication. A base controller for the admin namespace has been introduced, which includes the GitHub OAuthable module to enforce this protection, and provides a logout action to end the admin session.

app/controllers/admin · high confidence

Admin panel resources migrated to Avo 3

The admin panel's resource definitions have been upgraded to Avo 3, introducing a new configuration structure and UI components. This change adds dedicated admin views for new capabilities such as organization management (including invites, memberships, and onboarding), API key administration (with rename and revocation actions), and OIDC-based trusted publishing (covering providers, roles, and pending publishers). It also enhances existing resources with new filters and actions, including user creation and deletion, gem name reservations, and attestation repair, while updating search and display logic across resources like users, gems, and versions.

app/avo/resources · high confidence

Agent skills directory restructured

The .claude/skills path is now a symbolic link pointing to ../.agents/skills, centralizing agent skill definitions in the .agents directory.

.claude · high confidence

Audit logging requires a mandatory comment for resource actions

A new concern, AvoAuditableResource, has been added to enforce audit logging for Avo resource actions. When creating, updating, or destroying records, users are now required to provide a comment of at least 10 characters explaining the action, which is then saved to the audit log. This ensures that all significant changes to resources are traceable with context.

app/avo/resources/concerns · high confidence

Authenticated users can now view MFA status and warnings in their profile

The introduction of the \User::WithPrivateFields\ module modifies the user profile payload to include private multi-factor authentication details. When a user retrieves their own profile, the response now contains an \mfa\ field reflecting their current MFA level and a \warning\ field that provides localized guidance if MFA is recommended but not yet enabled or is set to a weak level. This allows users to see their security posture directly in the API response without exposing these sensitive details in public profiles.

app/models/user · high confidence

Avo 3 field view components for array, nested, and JSON fields

The admin interface's Avo fields now use dedicated view components for rendering in index, show, and edit contexts. Array fields support adding and removing nested items with error display, nested fields render their sub-fields in tables or lists, and JSON fields display formatted output in index views. These changes update how these specific field types are presented in the admin panel.

app/components/avo/fields · high confidence

Avo JavaScript loaded via Importmap

The Avo administration interface now loads its custom JavaScript assets using the Importmap system. This change replaces the previous asset loading mechanism with a new partial that explicitly includes the 'avo.custom' script via importmap tags, ensuring consistent and modern module resolution for Avo's client-side functionality.

app/views/avo/partials · high confidence

Compact index v2 format with content-addressable checksums

The compact index has been upgraded to a v2 format that includes content-addressable checksums and Ruby ABI information for each gem version. This change introduces new data structures (GemVersionV2) and serialization logic to embed checksums and platform-specific details directly into the versions list, enabling more efficient and reliable gem resolution for users.

_lib/compact\index · high confidence

Database schema and seed data updated for Rails 8.1

The database schema has been regenerated to reflect the current state of the application, now targeting ActiveRecord version 8.1 (schema version 2026\_09\_04\_073906). This update includes new tables and columns such as \admin\_github\_users\ for storing admin GitHub user data, \api\_keys\ with polymorphic ownership and scope arrays, \attestations\ for gem attestation data, and \deletions\ to track yanked versions. The seed data has been updated to create initial organizations, memberships, users, and gems that exercise these new structures, including API keys and admin users.

db · high confidence

Downloads API endpoints return 410 Gone

The new \Api::V1::Versions::DownloadsController\ explicitly deprecates the \index\ and \search\ endpoints by returning a 410 Gone status with a plain-text message indicating they are no longer supported. This change removes access to version download statistics via the API, signaling that these features have been retired or moved.

app/controllers/api/v1/versions · high confidence

Enhanced security, logging, and request handling infrastructure

This change introduces several foundational improvements to the application's request processing and observability. Security is hardened by adding a dedicated markdown rendering module that sanitizes HTML output using a strict allowlist of tags and attributes, preventing potential XSS vulnerabilities in policy pages. Request handling now includes robust IP address resolution with Fastly edge verification via proxy tokens, enabling accurate geo-IP tracking only for verified traffic while correctly identifying bypassed requests. Observability is significantly improved with a new structured logging payload that captures detailed context including the acting user or API key owner, HTTP details, and edge bypass status, alongside a new user-agent parser that accurately identifies clients like Bundler, RubyGems, and OIDC actions for better telemetry.

lib/gemcutter · high confidence

The server/gems directory is now a symbolic link pointing to the cache directory, replacing the previous unpacked structure. This change simplifies the file layout by removing the need to maintain a separate unpacked gems folder, as the gems are now accessed via the symlink.

server · high confidence

Homepage redesign with new search and support sections

The homepage has been completely redesigned to feature a prominent, large search box with autocomplete functionality, a display of the total download count, and a call-to-action to install RubyGems. Additionally, a new section highlights the platform's supporters and provides a direct link to donate via Ruby Central, replacing previous layout elements with a modern, responsive design using Tailwind CSS classes.

app/views/home · high confidence

Introduce Stimulus.js for interactive UI components

The application now uses Stimulus.js to manage client-side interactivity, replacing previous JavaScript implementations. This change introduces a suite of new controllers that enhance user experience: the autocomplete controller provides a responsive search-as-you-type experience with keyboard navigation; the password strength controller offers real-time visual feedback on password complexity; the onboarding name controller automatically generates URL-safe organization handles from display names; and the dump controller dynamically fetches and renders PostgreSQL database dump links from S3. Additional controllers handle specific UI behaviors such as avatar fallbacks, dialog management, dropdown toggles, and exclusive checkbox logic, creating a more consistent and maintainable frontend architecture.

app/javascript/controllers · high confidence

Introduce dedicated API key management and hardened authentication controllers

This change introduces a new ApiKeysController for managing user API keys (create, edit, update, destroy, and bulk reset) and a CompromisedPasswordsController to handle password reset flows flagged by HIBP checks. It also adds a new AvatarsController to proxy Gravatar images with caching, and a new OAuthController to handle GitHub OAuth for admin access. The ApplicationController is updated to include new security and caching helpers (like \deny\_shared\_cache\_when\_authenticated\ and \fastly\_expires\_in\), and several existing controllers (EmailConfirmations, MultifactorAuths, Passwords) are refactored to use stricter \params.expect\ and MFA verification flows.

app/controllers · high confidence

Introduce new ActionMailer-based email delivery and tracking

The application now uses a dedicated \ApplicationMailer\ base class that integrates SemanticLogger for delivery tracking and Roadie for automatic CSS inlining in HTML emails. All email notifications—including those for account changes, security events (MFA, API keys, password resets), gem operations (push, yank, ownership changes), organization invitations, and policy announcements—are now delivered via ActionMailer with ActiveJob backgrounding. This ensures emails are sent asynchronously and their delivery is logged as user events for monitoring.

app/mailers · high confidence

Introduces Pundit-based authorization for organizations, memberships, and gem ownerships

This change replaces previous access-control mechanisms with a new Pundit policy layer for the \app/policies\ directory. It introduces granular authorization for organization management (creating, updating, adding/removing gems, managing memberships, and reserving gem names) based on specific roles such as \:owner\, \:admin\, and \:maintainer\. It also standardizes ownership checks for RubyGems, ensuring that actions like adding, updating, or removing owners, as well as configuring trusted publishers, require appropriate ownership or organizational roles. This provides a consistent, role-based permission model for users interacting with organizations and gem ownerships.

app/policies · high confidence

Major API v1 controller refactoring and feature expansion

The API v1 controllers have been completely rewritten and expanded. New capabilities include an Activities API (latest and just\_updated endpoints), an Attestations endpoint for content-addressable gem support, a Deletions controller for yanking gems with Ruby ABI targeting, and a TimeframeVersions endpoint for querying versions by creation date. The Owners controller now supports role-based ownership management and lists gems by owner handle. The API Keys controller has been restructured to support scoped keys with MFA requirements and expiration dates. The Rubygems controller now accepts sigstore attestations during push and includes CORS support. Search functionality has been migrated to Elasticsearch with query sanitization and autocomplete. The Dependencies endpoint has been deprecated with a 404 response. Existing endpoints like Downloads, Profiles, and WebHooks have been refactored to use strong parameters, improved caching, and consistent JSON/YAML responses.

app/controllers/api/v1 · high confidence

Migrate JavaScript module loading to Importmap and restructure application entry points

The application now uses Importmap for JavaScript module resolution, replacing previous bundling or script-tag methods. The new \application.js\ entry point explicitly imports core libraries (Turbo, Rails UJS, LocalTime) and specific feature modules (OIDC API key form, pages, webauthn, github-buttons), while disabling Turbo's default drive behavior. Additionally, Avo admin customizations are now loaded via a dedicated \avo.custom.js\ file that registers the \stimulus-rails-nested-form\ controller, centralizing Stimulus controller registration.

app/javascript · high confidence

Migrate admin policies to the Admin:: namespace with Avo integration

All admin-facing Pundit policies have been moved into the Admin:: namespace (e.g., Admin::RubygemPolicy) and updated to inherit from a new Admin::ApplicationPolicy base class. This change introduces explicit Avo-specific permission methods (such as avo\_index?, avo\_show?, and act\_on?) to control access to the admin dashboard, and adds a has\_association helper to automatically define view permissions for related records. For users, this ensures that admin panel access is consistently enforced via the new policy structure, with scope resolution and association visibility properly scoped to rubygems\_org\_admins or specific user contexts.

app/policies/admin · high confidence

Migrate background jobs to ActiveJob with GoodJob adapter

The application has replaced the previous background job system with ActiveJob, using GoodJob as the adapter. This introduces a unified ApplicationJob base class with default retry policies and automatic discarding of deserialization errors. All existing background tasks—including gem indexing, Fastly log processing, CDN purging, webhook notifications, and user deletion—have been converted to ActiveJob jobs, allowing for better queue management, concurrency control, and observability via StatsD metrics.

app/jobs · high confidence

Migrate frontend scripts to vanilla JavaScript

The JavaScript codebase in app/javascript/src has been rewritten using vanilla JavaScript, removing the previous dependency on jQuery. This change includes new implementations for OIDC API key role forms (handling nested field addition/removal), MFA section toggling on the gems page, dynamic loading of transitive dependency lists, and WebAuthn credential registration and session handling. Users will experience the same functionality with a lighter, modern JavaScript stack that no longer relies on the jQuery library.

app/javascript/src · high confidence

Migrate to Tailwind CSS v4 configuration syntax

The application's Tailwind CSS setup has been updated to use the v4 configuration style. The main stylesheet now uses the new \@config\, \@import "tailwindcss"\, and \@plugin\ directives to load core styles and the forms, aspect-ratio, and typography plugins, replacing the previous compilation method.

app/assets/tailwind · high confidence

Multi-step UI for transferring RubyGems to an organization

The RubyGems transfer flow now uses a redesigned, multi-step interface that guides users through selecting the target organization, choosing which gems to transfer, and managing member permissions before finalizing. This update introduces a progress stepper, a summary view, and specific UI components for each step, including a 'Select all' checkbox for gems and a permission details accordion that explains the roles (Outside Contributor, Maintainer, Admin, Owner) available when inviting existing gem owners to the organization.

app/views/rubygems/transfer · high confidence

New admin access constraints for Rubygems.org

Added lib/constraints/admin.rb which defines access control logic for the admin interface. The file introduces a Matcher class that retrieves the admin user from the request header and validates their status, and a RubygemsOrgAdmin constraint that restricts access to users who are valid admins and specifically members of the 'rubygems-org' team. The file also enables frozen string literals for safety and performance.

lib/constraints · high confidence

New controller concerns for API keys, MFA, and auditing

This change introduces a suite of new controller concerns in the application to centralize and standardize key security and administrative behaviors. The \ApiKeyable\ concern provides utilities for generating and hashing unique RubyGems API keys. \ApplicationMultifactorMethods\ and \MfaExpiryMethods\ handle MFA redirection logic and session expiry management, ensuring users are guided to settings when MFA is required or expired. \RequireMfa\ and \SessionVerifiable\ enforce multi-factor authentication and session verification flows, including WebAuthn integration via \WebauthnVerifiable\. Additionally, \AvoAuditable\ and \MaintenanceTasksAuditable\ add audit logging capabilities to admin actions, while \JwtValidation\ and \LatestVersion\ handle JWT parsing and version lookups. These concerns replace scattered logic with reusable, testable components for authentication, authorization, and admin auditing.

app/controllers/concerns · high confidence

New dedicated admin login page with GitHub OAuth and dev mode support

Admin users now access the admin panel via a new, standalone login page at /avo/login.html.erb. This page provides a primary 'Log in with GitHub' button that initiates OAuth authentication (with Turbo disabled to ensure reliable session handling) and includes a fallback for development environments: when ENABLE\_DEVELOPMENT\_LOG\_IN is active, admins can directly log in as any existing GitHub admin user from a list, or create one by running db:seed. The page also links back to the main RubyGems.org site.

app/views/avo · high confidence

New global stylesheet with dialog and scrollbar utilities

A new global stylesheet (hammy.css) has been introduced to manage application-wide styles. This file defines specific styling for modal dialogs, including a semi-transparent backdrop that adapts to the system's dark mode preference, and provides utility classes to hide scrollbars across major browsers. It also includes a high-priority utility class to hide list items, ensuring it overrides conflicting Tailwind display utilities.

app/assets/stylesheets · high confidence

A new maintenance page has been added at public/maintenance/index.html, replacing previous inline or base64 assets with an external SVG image (gem\_wrench.svg) and a link to the real-time status page at status.rubygems.org. The page displays a simple 'Under maintenance' message and uses the site's static stylesheet.

public/maintenance · high confidence

New site layout system with breadcrumbs, session dialogs, and policy banners

The application introduces a new layout architecture in the views/layouts directory to support the redesigned user interface. This includes a new \_breadcrumbs.html.erb partial that renders a responsive, accessible breadcrumb trail for navigation context. A new \_session.html.erb partial replaces the previous header session controls, implementing a native HTML \<dialog\> component for the user profile menu and sign-in/sign-up actions. Additionally, a \_policies\_acknowledgement\_hammy.html.erb partial has been added to display a dismissible banner for new Terms of Service and Privacy Notice, allowing users to review and accept policies directly from the layout. These components are integrated into the main application.html.erb layout, which now serves as the base for specialized layouts like onboarding and subject (profile/organization) pages.

app/views/layouts · high confidence

Notifications for webhook deletion and automatic disabling

Users will now receive email notifications when a webhook is deleted or automatically disabled due to persistent failures. The new mailer views provide both HTML and text formats, detailing the specific webhook URL, the associated Ruby gem (if applicable), the reason for the action, and the number of failures that triggered the change.

_app/views/web\_hooks\mailer · high confidence

Production deployment configuration migrated to Kubernetes manifests and secrets

The production deployment configuration has been updated to use Kubernetes-native resources. Most deployment manifests (web, jobs, ingress, service, nginx config, etc.) are now implemented as symbolic links to shared templates, centralizing configuration management. Additionally, a new \secrets.ejson\ file has been added to store encrypted production secrets, including database URLs, AWS credentials, API keys for services like SendGrid and Fastly, and OAuth tokens, replacing previous secret management methods.

config/deploy/production · high confidence

Rails 7.2 configuration update and application booting improvements

The application's configuration initializers have been updated to align with Rails 7.2, including the adoption of the \:json\ cookie serializer and the \same\_site: :strict\ policy for session cookies. The boot process now enables the Zeitwerk autoloader, configures YJIT for performance, and registers custom ActiveModel types for Global ID and Duration. Additionally, the update introduces a cookie rotator to support graceful \secret\_key\_base\ rotation without forcing user logouts, and configures the application to use Semantic Logger for unified logging across components like Datadog, GoodJob, and Honeybadger.

config/initializers · high confidence

Rails 8.0 environment configuration overhaul

The application environment files (development, test, staging, production) have been updated to align with Rails 8.0 defaults and best practices. Key changes include replacing \config.eager\_load\ with \config.enable\_reloading\ for controlling code reloading, disabling \config.action\_dispatch.show\_exceptions\ in the test environment to prevent debug template rendering issues, and enforcing random test execution order via \config.active\_support.test\_order = :random\. The production and staging environments now explicitly configure Memcached with a 2MB value max size and JSON semantic logging, while the development environment supports a \PROFILE\ environment variable to switch to production-like settings for benchmarking.

config/environments · high confidence

Redesign of the gem dependencies page with reverse dependencies

The gem dependencies view has been completely redesigned to present dependencies in a structured table format, separating runtime and development scopes. The page now explicitly displays required version constraints for each dependency and includes a new section listing reverse dependencies (gems that depend on the current gem), showing their latest version, release date, and download counts. This replaces the previous list-based layout with a more detailed, tabular presentation that improves readability and provides deeper context about the gem's ecosystem.

app/views/dependencies · high confidence

Redesigned API key management with granular scopes and expiration

The API keys settings page has been redesigned to support more granular control and security. Users can now create and edit API keys with specific gem scopes, set expiration dates, and enable multi-factor authentication (MFA) on a per-key basis. The interface displays all gems if no specific gem scope is selected, and the key index view has been paginated for better usability. Additionally, the form has been converted to use Stimulus controllers for exclusive checkbox behavior, and the layout has been updated to use Tailwind CSS classes.

_app/views/api\keys · high confidence

Redesigned MFA verification and recovery code pages

The multifactor authentication verification and recovery code views have been redesigned with a modern UI, featuring a centered card layout, dark mode support, and updated styling. The MFA prompt page now consolidates WebAuthn and TOTP/recovery code entry into a single flow, while the recovery code page introduces a clickable copy-to-clipboard feature for the generated codes and requires explicit user acknowledgment before continuing.

_app/views/multifactor\auths · high confidence

Redesigned OIDC API key roles and trusted publisher management interfaces

The OIDC settings pages have been redesigned to use Phlex view components, providing a modernized interface for managing API key roles, access policies, and trusted publishers. Users can now create and edit API key roles with granular access policies (defining effects, principals, and conditions), view detailed permission scopes, and manage GitHub Actions workflow integrations. The redesign also introduces dedicated pages for listing and configuring trusted publishers (including GitHub Actions) for both global and per-gem contexts, with improved navigation, consistent styling, and clearer presentation of configuration details.

app/views/oidc · high confidence

Redesigned TOTP setup interface with modern styling

The TOTP setup view has been redesigned to provide a cleaner, more modern user experience. The new interface features a centered card layout with improved typography and spacing, displaying the QR code, account details, and secret key more clearly. The input field for the OTP code now includes better visual feedback with focus states and uses a primary color button for submission, enhancing usability and accessibility.

app/views/totps · high confidence

Redesigned UI components using Phlex

The application's view layer has been migrated to Phlex, introducing a suite of new Ruby-based UI components (Alert, Button, Card, Tooltip, etc.) that replace the previous view templates. This change brings a consistent, modern design system with updated styling, dark mode support, and improved accessibility across the interface, including redesigned navigation, event tables, and OIDC/trusted publisher forms.

app/views/components · high confidence

Redesigned WebAuthn verification flow with dedicated status pages

The WebAuthn verification interface has been redesigned to provide clearer feedback during the authentication process. Users now encounter a dedicated prompt page that displays their name and initiates the WebAuthn session, replacing the previous generic view. Upon completion, the system redirects to distinct success or failure pages: the success page confirms the verification with a checkmark, while the failure page displays an error icon and any specific error message returned by the backend, helping users understand why the attempt did not succeed.

_app/views/webauthn\verifications · high confidence

Redesigned email confirmation request page

The email confirmation request interface has been updated with a modern, responsive design. Users now see a centered card layout with clear typography and form styling, including a dedicated email input field and a primary submit button, improving the visual consistency and usability of the email confirmation flow.

_app/views/email\confirmations · high confidence

Redesigned gem show and index pages with new layout and components

The gem show and index pages have been completely redesigned with a new layout structure. The main show page now uses a two-column layout with a new aside sidebar displaying version info, download counts, MFA status, and GitHub stars, alongside a secondary sidebar for links, licenses, and owners. The index page now uses a card-based layout with alphabet directory navigation. New components include tabbed navigation for gem info and dependencies, version navigation links, and dedicated views for yanked gems with unsubscribe options. The redesign also adds security event logging views, reserved namespace pages, and improved owner management displays with MFA warnings.

app/views/rubygems · high confidence

Redesigned organization membership management interface

The organization membership views have been completely redesigned with a new layout and styling. The members index page now displays a list of members with their roles (or 'pending' status for unconfirmed invitations) and provides an invite button for authorized users. A new edit page allows administrators to change a member's role and includes a 'Joined' date for confirmed members, as well as a button to resend invitations to pending members. The new invitation page enables admins to invite new members by entering a user handle and selecting a role. All views use a consistent card-based layout with breadcrumb navigation.

app/views/organizations/members · high confidence

Redesigned organization onboarding flow with step-by-step wizard

The organization creation process has been restructured into a multi-step wizard to guide users through setup more clearly. The new flow includes distinct stages for naming the organization (including the permanent handle), selecting associated gems, and managing member invitations, all tracked by a visual progress indicator. A summary view is now available at each step to review selections, and the final confirmation screen explicitly warns that the organization handle is permanent and cannot be changed without support assistance.

app/views/organizations/onboarding · high confidence

Redesigned owners management interface with role-based access and self-removal confirmation

The owners index and edit pages have been redesigned to use a new layout, featuring a responsive table that displays owner name, confirmation status, MFA status, authorizer, role, and confirmation date. Users can now add new owners by specifying a handle and selecting a role, and existing owners can have their roles updated via the edit page. A key behavioral change is the requirement for username confirmation when a user attempts to remove themselves as an owner, adding a safety step to prevent accidental loss of access.

app/views/owners · high confidence

Redesigned password reset and edit forms with API key reset options

The password reset workflow now uses custom, redesigned views for requesting a reset link (new), entering a new password (edit), and confirming success (create). The edit form includes a password strength meter, displays alerts if the password was found in a breach (HIBP), and allows users to optionally reset their API keys or all scoped API keys during the password change. The forms use modern styling with dark mode support and Turbo-disabled submission for the edit action.

app/views/passwords · high confidence

Redesigned reverse dependencies page with new search and table layout

The reverse dependencies view has been completely rewritten to feature a modern, responsive design. Users now see a dedicated search form at the top of the page to filter reverse dependencies by query. The list of dependencies is displayed in a clean table format showing the gem name, version, date, and download counts, with mobile-friendly adjustments that hide less critical columns on smaller screens. Pagination has been simplified to use a 'plain paginate' helper, removing the explicit page number links in favor of a more streamlined navigation experience.

_app/views/reverse\dependencies · high confidence

Redesigned search interface with advanced filtering and aggregation stats

The search experience has been redesigned to include a dedicated Advanced Search page and enhanced result displays. Users can now access advanced filtering options via a new form that allows searching by name, summary, description, downloads, and update date, powered by a Stimulus.js controller for interactive input handling. Search results pages now feature a new aggregation bar that displays match counts for different fields, date range filters, and yanked gem status, alongside improved pagination and search suggestion prompts. The layout utilizes new UI components like CardComponent and RubygemComponent for a consistent visual style.

app/views/searches · high confidence

Redesigned settings page with WebAuthn support and new account navigation

The settings edit page has been redesigned to include a dedicated section for managing WebAuthn credentials, displaying a status badge and allowing users to add new keys. The Multi-Factor Authentication (MFA) section now explicitly shows the MFA level for enabled accounts and provides controls for TOTP. Additionally, the Account section has been updated to include direct links to API keys, OIDC pending trusted publishers, and OIDC API key roles, improving visibility for these features.

app/views/settings · high confidence

Redesigned sign-in and verification pages with modern styling

The sign-in and password verification pages have been updated with a new visual design, featuring a centered card layout, improved spacing, and support for dark mode. The login form now accepts either an email address or a handle in the 'who' field, and the password input includes the 'current-password' autocomplete attribute to assist password managers. Additionally, the verification page now conditionally displays a WebAuthn prompt if the user has multi-factor authentication enabled.

app/views/sessions · high confidence

Redesigned static pages with new content and components

The static pages in the application have been completely redesigned and updated. The About page now features a structured layout with purpose statements, founding history, and sponsor acknowledgments, including a direct link to download logos. The Download page has been updated to display the latest RubyGems version dynamically, providing clear manual and automatic upgrade instructions alongside buttons for various distribution formats (tgz, zip, gem, git). A new Data page offers access to sanitized weekly PostgreSQL data dumps, utilizing a Stimulus.js controller for dynamic list rendering. The Security page has been restructured to clarify reporting procedures for RubyGems client issues versus gem vulnerabilities, explicitly stating that monetary bug bounties are no longer offered, and includes a direct link to the new Security Engineers in Residence FAQ. This FAQ page details the new program funded by Alpha-Omega and run by Ruby Central, explaining the team's process for scanning, verifying, and disclosing vulnerabilities in the Ruby ecosystem. The Supporters page now highlights the RubyGems Supporter Program, listing open-source sponsors and infrastructure donors. Additionally, a new index page provides a central list of all available static pages.

app/views/pages · high confidence

Redesigned stats page with modern UI and pagination

The stats page has been completely redesigned with a modern, responsive layout using Tailwind CSS classes for cards, grids, and typography. Key changes include the addition of pagination for the 'most downloaded gems' list (using the Kaminari gem), improved number formatting with delimiters, and the integration of a Stimulus.js controller for animated download meters. The page now features a cleaner visual hierarchy with icon-tagged labels, a prominent 'Click Gems' call-to-action button, and dark mode support.

app/views/stats · high confidence

Redesigned user dashboard with sidebar navigation and organization promotion

The dashboard view has been completely redesigned to feature a new layout with a sidebar navigation component (\\_subject.html.erb\) that includes links to the dashboard, subscriptions, settings, and organizations (for members). The main content area now displays a promotional banner for the new Organizations feature (visible only to users with the feature flag enabled and no existing memberships), followed by cards showing the user's latest gem updates, owned gems, and subscribed gems. This change introduces a modern UI structure with Tailwind CSS styling and integrates the new Organizations capability directly into the user's primary landing page.

app/views/dashboards · high confidence

Redesigned user profile pages with modern UI and new security features

The user profile experience has been completely overhauled with a new visual design, introducing dedicated pages for viewing profile details, editing settings, and deleting accounts. The public profile now displays the user's handle, full name, email (if public), and X/Twitter username, alongside a list of their published gems with version and download counts. Users can now edit their profile to update their handle, Twitter username, email, and full name, with validation requiring a password for changes. A new 'Delete Profile' page allows users to permanently remove their account, listing any gems they solely own that would be affected. Additionally, a new Security Events view has been added, allowing users to review their account's security activity via a dedicated Phlex-based component.

app/views/profiles · high confidence

Redesigned user sign-up form with handle and public email options

The user sign-up experience has been redesigned with a new form layout that now requires users to set a handle in addition to their email and password. The form includes a new optional full name field and a checkbox to allow users to make their email public. The password field has been updated to include the autocomplete attribute set to 'new-password' for better security and browser compatibility. The sign-up page also displays a link to the terms of service and respects the signup\_enabled? configuration to allow or disable new registrations.

app/views/users · high confidence

Redesigned versions list and added Atom feeds

The versions index page has been redesigned with a modern layout, displaying version numbers, dates, platforms, Ruby ABI, and file sizes in a paginated list. A new partial renders individual version items with styling for yanked gems. Additionally, Atom feeds have been added for both the global latest gems and per-gem version histories, allowing users to subscribe to version updates.

app/views/versions · high confidence

Refactored admin authentication and added new middleware for hosting and redirects

Admin authentication logic has been extracted into a dedicated \AdminAuth\ middleware, which now handles GitHub OAuth for the \/admin\ namespace and ensures session cookies are set on the login page, while explicitly allowing unauthenticated access to \/oauth\ paths. A new \Hostess\ middleware manages static file serving for gem specs and indexes, including tracking downloads for \.gem\ files. Additionally, a \Redirector\ middleware enforces canonical hostnames by redirecting requests from non-allowed hosts to the primary site, excluding API and internal paths.

lib/gemcutter/middleware · high confidence

Restrict RubyGem event management to owners

A new policy for RubyGem events has been introduced that restricts all write operations (create, update, and destroy) to return false, effectively disabling these actions for all users. The only permitted action is viewing events (show), which is now gated by an ownership check, allowing access only if the current user owns the associated RubyGem.

app/policies/events · high confidence

SQS worker now enqueues Fastly log processing jobs via Active Job

The SQS worker has been updated to process incoming S3 log records by creating LogTicket records and enqueuing FastlyLogProcessorJob instances using Active Job, replacing the previous direct processing logic. This change introduces StatsD instrumentation to track metrics for fetched entries, enqueued jobs, and duplicate record attempts, and ensures the worker class is properly loaded by adding the lib folder to eager\_load\_paths.

lib/shoryuken · high confidence

Standardize styling for static pages and admin login

A new static stylesheet (static.css) has been introduced to centralize visual presentation for error pages and the admin login interface. This change removes previously inline styles from error pages, ensuring consistent typography, layout, and spacing across these views. It also defines specific styles for the admin login button and error illustrations, including a bounce animation for the error page graphic, replacing the previous ad-hoc styling approach.

public/stylesheets · high confidence

Standardized error pages and search configuration

The site now serves consistent, branded HTML error pages for client and server errors (400, 403, 404, 406, 422, 500, 502, 503) using a unified layout and SVG illustrations. Search engine indexing is controlled via a new robots.txt file that disallows /search, /downloads, /gems?letter=\*, /names, and /news. Additionally, an OpenSearch description file has been added to enable native browser search integration for RubyGems.org.

public · high confidence

Upgrade to Rails 8.1 defaults and modernize application configuration

The application configuration has been updated to load Rails 8.1 framework defaults, bringing new baseline behaviors and security settings. This change includes migrating the background job adapter to Good Job, enabling the bootsnap caching library for faster boot times, and configuring the middleware stack with Rack::Sanitizer, Rack::Attack, and Rack::Deflater. Additionally, the application now uses Flipper for feature flagging, sets the Cross-Origin-Opener-Policy to same-origin for improved security, and configures specific autoload paths for views and components.

config · high confidence

Test coverage

Added Fastly sample log fixture for testing; Added admin policy tests for Avo dashboard resources; Added component tests and Lookbook previews; Added factory for MaintenanceTasks::Run; Added functional tests for API v1 controllers; Added functional tests for API v2 contents and versions endpoints; Added functional tests for OIDC API key roles controller; Added functional tests for core controllers; Added functional tests for organization features; Added functional tests for organization onboarding controllers; Added functional tests for the RubyGems transfer workflow; Added integration test for GoodJob admin dashboard access; Added integration tests for API v1 endpoints; Added integration tests for API, security, and organizational features; Added integration tests for Avo admin dashboard resources; Added integration tests for OIDC profile pages; Added integration tests for the API v2 version information endpoint; Added mailer previews and automated tests for email notifications; Added model tests for API keys, attestations, and gem management; Added model tests for Admin::GitHubUser; Added model tests for MFA, search, and compact index concerns; Added policy tests for API authorization; Added policy tests for organization, membership, and gem ownership authorization; Added system tests for new and redesigned UI features; Added test coverage for OIDC model validations and relationships; Added test coverage for background job suite; Added test coverage for mailer templates and delivery behavior; Added test factories for OIDC integration testing; Added test factories for core domain models; Added test factories for security event logging; Added test fixture for sigstore attestation verification; Added tests for API deprecation routing; Added tests for Gemcutter configuration loading; Added tests for MFA warning logic in user JSON serialization; Added tests for OIDC Trusted Publisher GitHub Action model; Added tests for OIDC trusted publisher policies; Added tests for RSTUF job lifecycle; Added tests for Rubygem event policy; Added tests for access control, compact index, markdown rendering, password breach checking, and search query sanitization; Added tests for compact index dependency and version handling; Added tests for internal ping and revision endpoints; Added tests for maintenance tasks; Added tests for the audit attestation subject digest rake task; Added tests for the versions downloads controller; Added tests for user, rubygem, and user agent event models; Added unit tests for Avo admin actions and filters; Added unit tests for Duration and JsonDeserializable types; Added unit tests for Hostess and Redirector middleware; Added unit tests for certificate chain serialization, ERB safety, and infrastructure components; Added unit tests for helper methods; Added unit tests for request IP address handling and user agent parsing; Added unit tests for the RSTUF API client; Integration tests for OIDC API endpoints; Integration tests for the Compact Index API; Migrate system tests to Playwright and establish new test infrastructure; New test helpers for admin, API policies, Avo, compact index, Datadog, email, search, feature flags, gems, OAuth, passwords, policies, rake, rate limits, and WebAuthn; System tests for Avo admin actions.

Dependencies

Upgrade Ruby to 3.4.3 and RubyGems to 3.6.8

The application runtime has been upgraded to Ruby 3.4.3, with RubyGems updated to version 3.6.8. This ensures the application runs on the latest stable Ruby release, providing performance improvements and security patches.

(dependencies) · high confidence

Upgrades Stimulus to v3.2.2 and adds @rails/ujs v7.1.3-4

The vendor JavaScript bundle now includes @hotwired/stimulus version 3.2.2 and @rails/ujs version 7.1.3-4. This update brings the latest Stimulus features and bug fixes to the application's controller system, while the inclusion of @rails/ujs provides legacy unobtrusive JavaScript helpers (such as remote form handling and CSRF protection) that may be required by existing views or gems like Avo.

vendor/javascript · high confidence

Housekeeping

Added empty reports directory placeholder; Placeholder for asset builds directory.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 49.

Lenses

  • Code Health 70
  • Architecture 88
  • Maturity 56
  • Readiness 80
  • Security 50
  • Domain Modelling 41
  • Accessibility 56

Changes since last survey

  • 300 commits — 275 feature/other, 25 fixes

By area

  • (root) — 69 commits
  • (repo) — 55 commits
  • .github/workflows — 21 commits
  • app/models — 21 commits
  • app/views — 15 commits
  • config/locales — 13 commits
  • db/migrate — 13 commits
  • app/controllers — 12 commits
  • config/initializers — 12 commits
  • app/avo — 10 commits
  • config/deploy — 7 commits
  • test/functional — 7 commits
  • test/models — 6 commits
  • app/tasks — 4 commits
  • .devcontainer/devcontainer-lock.json — 3 commits
  • .github/actions — 3 commits
  • .github/dependabot.yml — 3 commits
  • lib/gemcutter — 3 commits
  • test/integration — 3 commits
  • .agents/skills — 2 commits

Notable commits

  • fix: Fix Avo unblock user action (#6774)
  • fix: Fix Deprecation: Use skip instead of add_filter for simplecov (#6732)
  • fix: Fix GoodJob StatsD result counter (#6767)
  • fix: Fix RuboCop refute assertions
  • fix: Fix business logic events signup tracking (#6612)
  • fix: Fix flaky Rails test failure in API v1 downloads yanked-gem case (#6809)
  • fix: Fix gem transfer when co-owners are already organization members
  • fix: Fix password reset links with strict SameSite cookies (#6794)
  • fix: Fix password reset token migration (#6770)
  • fix: Fix reusable workflow attestation verification (#6811)
  • fix: Fix simple_markup for RDoc 8
  • fix: Fix some more RuboCop refute assertions
  • fix: Isolate the names cache to fix a flaky compact index test
  • fix: Merge pull request #6728 from mvanhorn/fix/6695-owner-profile-latest-version
  • fix: Merge pull request #6768 from rubygems/ab/fix-gem-transfer-existing-org-members
  • fix: Merge pull request #6783 from rubygems/revert-abi
  • fix: Merge pull request #6857 from rubygems/copilot/fix-rubocop-failure-again
  • fix: Revert "Make version index cleanup idempotent (#6782)"
  • fix: Revert "Merge pull request #6674 from Shopify/ho/feature-branch-ca-server-changes"
  • fix: fix: read the admin header by name in the logger; lib/github_oauthable.rb loads before SimpleCov starts, so any line added there is uncovered (this is how it was before)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rubygems/rubygems.org was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ad83daf211de083abcdaa61c7ae5cfb5d495fb01 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.